Short Name |
HTTP:STC:IE:UNINIT-DOM |
---|---|
Severity |
High |
Recommended |
No |
Recommended Action |
Drop |
Category |
HTTP |
Keywords |
Microsoft Internet Explorer Uninitialized DOM Memory Corruption |
Release Date |
2010/10/18 |
Update Number |
1794 |
Supported Platforms |
idp-4.0+, isg-3.1.134269+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attempts to exploit a known vulnerability in Microsoft Internet Explorer. It is due to a memory corruption that can occur when Internet Explorer handles uninitialized DOM. Remote attackers can exploit this by enticing target users to visit a malicious Web page. A successful attack can result in execution of arbitrary code on the vulnerable system in the context of the logged-on user. If successful, the attack behavior of the target machine is dependent on the intention of the malicious code. In an unsuccessful attack, the associated browser tab can terminate abnormally and then the browser will recover it.
Microsoft Internet Explorer is prone to a remote code-execution vulnerability. Attackers can exploit this issue to execute arbitrary code in the context of the user running the application. Successful exploits will compromise the application and possibly the computer. Failed attacks may cause denial-of-service conditions.